Terminology Index
1801 terms
Showing 897-928 of 1801 terms
Indicator Extraction
Pulling concrete indicators, such as file hashes, domains, IPs, or behavioral patterns, out of a threat hunt's findings, so what the hunt discovered can be operationalized into detections and shared intelligence.
Indicator Pivot
Using one observed indicator on a host, such as a suspicious process, path, or registry key, as a starting point to find related artifacts and expand understanding of what an attacker did on the system.
Indicator Pivoting
An analyst investigation skill of moving from one indicator to related ones, an IP to the domains it hosts, a hash to where else it appears, to expand an investigation and uncover the full scope of activity.
Indicators of Attack
Signals that focus on attacker behavior and intent, the actions and techniques being carried out, rather than static artifacts. They detect attacks in progress even when no known indicator of compromise is present.
Indicators of Compromise
Observable artifacts that signal a system may be compromised, such as malicious file hashes, IP addresses, domains, or registry keys, used to detect, hunt for, and confirm known threats across an environment.
Industry Framework Selection
Choosing security frameworks based on an organization's industry and its specific regulatory and customer demands, since sectors like healthcare, finance, and government gravitate toward frameworks suited to their obligations.
Industry Sharing
The practice of organizations sharing threat intelligence with one another, often through industry groups like ISACs, so defenders benefit from collective knowledge of threats targeting their sector.
Industry-Specific Cloud Frameworks
Cloud compliance frameworks tailored to particular industries, such as healthcare, finance, or government cloud requirements, that an organization must meet on top of general cloud compliance when operating in a regulated sector.
Information Security Policy
The high-level policy that sets an organization's overall direction and requirements for protecting information, the foundational governance document from which more specific policies, standards, and procedures flow.
Infrastructure as Code
Managing infrastructure with versioned configuration files instead of only manual changes.
Ingress
Network traffic entering a network or host, inbound flows from outside. Controlling ingress with firewalls and access rules is fundamental to limiting what can reach internal systems and reducing attack surface.
Inherence Factor
An authentication factor based on something you are, a biometric trait like a fingerprint, face, or iris, used to verify identity. It is one of the three classic factor categories alongside knowledge and possession.
Inherent Risk
The level of risk that exists before any controls are applied, the raw exposure of an activity or asset on its own. It is compared with residual risk (after controls) to show how much controls reduce risk.
Inheritable Controls
Controls that a cloud customer can rely on the provider to fulfill under shared responsibility, so the customer inherits them rather than implementing them, reducing the customer's own compliance burden for those controls.
Initial Access
The first successful foothold an attacker gains in an environment.
Initial Access Hunts
Threat hunts focused on finding how attackers first got in, searching for signs of phishing payloads, exploited services, or other initial-access techniques that may have established an undetected foothold.
Initial Assessment
An analyst's first evaluation of an alert, quickly judging what it is, how urgent and severe it appears, and what to do next, to triage it efficiently before deeper investigation.
Initial Communication
The first communications sent when an incident is confirmed, notifying the right internal people and stakeholders that an incident is underway, establishing channels and cadence so coordination starts on the right foot.
Initial Response
The first hands-on actions taken once an incident is confirmed, stabilizing the situation, beginning containment where needed, preserving evidence, and mobilizing responders, before the fuller investigation and response unfold.
Initial Scoping
Determining the breadth of an incident early on, which systems, accounts, and data are affected and how far the compromise reaches, so response is sized correctly and nothing affected is missed.
Injection
A class of web vulnerabilities where untrusted input is interpreted as commands or code, such as SQL or command injection, letting an attacker alter queries or execute unintended actions. Input validation and parameterization are the defenses.
Input Validation
Checking external input against expected rules before the application trusts or stores it.
Insider Activity Alerts
SOC alerts flagging potentially malicious or risky behavior by insiders, employees or contractors, such as unusual data access, policy violations, or signs of misuse, that analysts triage with care given the human and legal sensitivity.
Insider Risk
The risk posed by people inside the organization, employees, contractors, partners, who through malice, negligence, or compromise could harm security. It spans the full range from accidental mistakes to deliberate sabotage or theft.
Insider Threat Response
The response to a confirmed or suspected insider threat, handled with special care for evidence, legal involvement, and discretion, since the subject is a trusted person with legitimate access and the matter carries HR and legal weight.
Insider Threats
Threats that come from people with legitimate access, malicious insiders stealing or sabotaging, negligent insiders causing accidental harm, or compromised insiders whose access an attacker has hijacked. They bypass perimeter defenses.
Integrity
Integrity means information or systems remain accurate, complete, and protected from unauthorized change.
Intelligence Cycle
The structured process of producing threat intelligence, planning and direction, collection, processing, analysis, and dissemination, that turns raw data into finished intelligence and feeds back into new requirements.
Intelligence Integration
Weaving threat intelligence into all SOC functions, detection, triage, hunting, and incident response, so intelligence actively shapes operations rather than sitting in isolated reports. It is what makes a SOC threat-informed.
Intelligence Reports
The finished intelligence products a SOC produces or consumes, written assessments of threats, actors, campaigns, or indicators, tailored to an audience so decision-makers and operators can act on the analysis.
Intelligence Requirements
The defined questions an intelligence effort sets out to answer, what the organization needs to know about threats to make decisions, that direct collection and analysis so intelligence is purposeful rather than aimless.
Intelligence in Detection
Applying threat intelligence to detection, using knowledge of adversary indicators and techniques to build, prioritize, and enrich detections, so the SOC catches what intelligence says is actually threatening it.